Netskope Threat Labs

Syskit

ATP Sandbox Adv. Heuristics

Syskit is a remote access trojan associated with Iranian threat actors, used in campaigns that included attacks on US veterans' organizations and IT providers in Saudi Arabia, with researchers observing its use by the Tortoiseshell group and related actors such as TA456.

First seen
April 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.Syskit
Win32.Backdoor.Syskit